Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24623
HistoryApr 10, 2020 - 12:59 a.m.

Arbitrary Code Execution

2020-04-1000:59:27
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16

0.186 Low

EPSS

Percentile

96.2%

pango is vulnerable to arbitrary code execution. The vulnerability exists as an input sanitization flaw, leading to a heap-based buffer overflow, was found in the way Pango displayed font files when using the FreeType font engine back end. If a user loaded a malformed font file with an application that uses Pango, it could cause the application to crash or, possibly, execute arbitrary code with the privileges of the user running the application.